Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Q&A: Head of PCI council sees security standard as solid, despite breaches

GM Bob Russo defends payment card rules but acknowledges that 'interpretation issues' remain

Zone

Featured Zone
The Security Zone

With the mobility of employees and the ease with which external devices can be brought in and out of a network, continuing to build your security plan for network servers and clients is a must. Fortunately, there is much that organizations can do to protect themselves from attacks - internal and external. Having the right policies, procedures and server configurations is critical...

Learn more in The Security Zone
See All Zones

April 16, 2008 (Computerworld) The PCI Security Standards Council was established by the major credit card companies in September 2006 as an independent organization to manage the Payment Card Industry Data Security Standard. In an interview with Computerworld, general manager Bob Russo talks about the council's efforts to administer the PCI standard amid continuing concerns about credit and debit card security. And he defends the standard, despite the recent data breaches at Hannaford Bros. Co. and Okemo Mountain Resort.

What has the PCI council been up to? I started in 2007. My job in the first year was basically to brand the council. I think we did a reasonable job of branding the council and getting everybody to know what we are doing, and getting everybody to know the standard. My mouth wrote a lot of checks in 2007. So 2008 is when we have to start cashing those checks. Right in the first three months of this year, we have already begun to do this.

At the beginning of this year, we issued the PIN Entry Device standard. Then we released a new self-assessment questionnaire. That was the direct result of feedback from our stakeholders from the industry, from small merchants who said we can't answer 207 questions (which is the number of questions in the standard SAQ). So we broke up the SAQ into five distinct versions specific to what people are doing in terms of their businesses, down to where in some cases, you only have to answer 11 questions in order to get compliant.

This month, we are releasing the payment application standard. June 15 is when [PCI Section] 6.6 goes into effect (relating to Web application firewalls). September is when we are going to be releasing the next version of the data security standard.

What can you tell us about the next version? I can't really say if it's going to be a revision or if it's going to be a new version number. But there's going to be a lot of clarifications and a lot of guidance in it, because we still get questions about ambiguity.

One of the areas that will be touched on is probably wireless. There will be some updates. I can't tell you any specifics on what the updates are. But there will be some updates in the wireless area and probably in the application area and the preauthorization area as well -- but not so much that it's going to change the way you do business. Of course, if a major change has to be made, and if it puts people out of compliance, then we will make it a best practice for a certain period before making it a requirement.

We are also starting a QA program for our qualified security assessors. Right at this point, we are at the beginning stages. We'll probably begin the program sometime in the second quarter, and by the third quarter, we should be in full swing. We get a lot of questions from merchants about, "Why is this company charging $50,000 and why is this guy charging only $10,000? There has got to be something that one of them is doing differently." We are making sure everybody is on a level playing field, above and beyond what we already do. We already vet these companies, we make sure that they go through our training, make sure they are tested, make sure they are requalified every year. So it's above and beyond all this.

What PCI controls do people find most ambiguous? There's a lot of disagreement over compensating controls. Right now, people think that if they are not doing what the standard says, they have the ability to come out with a compensating control. Well, you do have the ability to do that. But a compensating control has to be both above and beyond what the standard calls for. The standard is the baseline. If you have a compensating control you want to submit, it has got to be above and beyond what the standard is calling for.

There are interpretation issues as well -- interpretation by the QSAs, interpretation by the merchants, interpretation by the brands. For some of the larger merchants that have been around for a while, you are talking about legacy systems that have been running their business quite well for 15 to 20 years. To try and retrofit these legacy systems with security is not an easy thing. It's easier to build a brand-new application and build the security into them right now than it is to take a legacy system and build in new security. The very last thing you want to do is break your business. So these really are the biggest concerns that merchants have.

Why aren't the Big Four accounting firms among your list of qualified assessors? They were at one point, weren't they? They had some liability issues that they weren't ready to sign up for. They look at it and say, "This is a small company here which is a QSA. Maybe it's a $2 million or a $3 million or a $10 million business, and here we have a multibillion-dollar business. Our liability is a lot worse." We are doing a couple of things behind the scenes to see if we can rectify that.



What People Are Saying

Shark Bait
View Shark BaitFired up about IT? Join Sharkbait and share your true tales of IT. SharkBait is the place for you to sound off about everything IT – the good, the bad, and the rest of the weird stuff you deal with every day.

New baits
Shark Bait
Webcast

Turning information into a Competitive Advantage "Turning information into a Competitive Advantage"

Companies today are realizing that competitive advantage is harder to sustain when based solely on gains in productivity and cost efficiency. The focus is shifting to invest more in business optimization initiatives which rely on trusted information to develop new insights that deliver better business results. But how can this be done efficiently in a business environment across multiple applications and processes. The answer is an Information Agenda - an innovative approach to transforming business information into a strategic asset for competitive advantage.

View this webcast now! more

See more Webcasts more
TODAY'S TOP BLOG
Patrick Thibodeau:
Satellite images of U.S military bases
Which is more important? Helping terrorists or protecting military bases? Answer: protecting Web 2.0 ... [more]
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
The 2008 ERP in Manufacturing Benchmark Report Summary
IronPort Web Reputation Filters Tech Note
Designed to Manage Lean Principles
View more whitepapers 
 


Webcast: The Automation of IT Compliance Programs: Reducing Risk, Cost and Complexity of Corporate Compliance
To meet the growing number of industry and federal regulations, businesses spend significant time, effort, and budget determining how to best meet continuously evolving IT compliance requirements this new Forrester Research and Juniper Networks Webcast led by industry experts who examine global IT security and compliance trends, common IT compliance issues and challenges, and best practices for successful IT compliance programs.

View this webcast 
Whitepaper: Tackling the Top Five Network Access Control Challenges
The major challenge enterprises face today is how to create innovative business models and to increase productivity by opening the network to a dynamic workforce, while at the same time protecting critical assets from the vulnerabilities that openness and user mobility bring. In addition, to comply with industry and governmental regulations, enterprises must prove that they have stringent controls in place to restrict access to sensitive data. This paper describes the top five networking access control challenges that companies like yours are facing and solutions that they are deploying today.

Download this white paper 
Whitepaper: Addressing PCI Compliance with a Comprehensive Network Access Control Solution
The Payment Card Industry (PCI) is one of the most comprehensive data security standards in a cluster of regulations that have emerged over the past decade. Meeting its requirements is both complicated and expensive for many companies. Learn how a comprehensive access control solution allows retailers and consumer organizations adhere to the core tenets of PCI, and delivering the necessary information and reports needed for compliance audits.
Download this white paper 
Whitepaper: Control System Cyber Vulnerabilities and Mitigation of Risk for Utilities
Today's global industrial infrastructure includes thousands of electric utilities, water/wastewater management companies, oil and gas suppliers, chemical manufacturers and other facilities critical to daily functioning. Learn why relying on off-the-shelf operating systems and Internet-based remote access control to carry out production tasks, traditional control networks can leave today's global industrial infrastructures vulnerable to hackers, extortionists, worms, viruses and application-level attacks. Deploying network-based security can protect these at-risk systems–without requiring infrastructure replacement.
Download this white paper